This afternoon I upgraded from 7.0.15 to 7.2.10 and to my surprise the packet capture GUI changed to complete garbage. Not only that, I have lost the ability to capture multiple interfaces like before.
Is there any way to get the ability to capture multiple interfaces into their own pcaps like before?
Maybe it is hidden in the cli somehow?
Hi,
Please refer to this article for packet capture using GUI:- https://docs.fortinet.com/index.php/document/fortigate/7.2.0/administration-guide/462154
you can also capture packets via CLI:- https://docs.fortinet.com/document/fortiweb/7.6.0/troubleshooting-guide/715676/packet-capture-via-c...
Yes there has been changes in the layout, but you can still run the parallel packet captures on the GUI.
You just will have to go to Diagnostics under Network, and start on new capture, close it, and then start it again on different interface.
 
This change was necessary/desirable to avoid lots of "duplicate message" (in red or black) in Wireshark view.
In other words, use "diag sniffer packet any .... 4 0 l" in CLI if you need to see how one packet comes in/through/out the chain of interfaces.
Toshi
Created on
‎04-10-2025
02:59 PM
Edited on
‎04-10-2025
09:49 PM
By
Anthony_E
I'm just going to say I agree with complete garbage, even as explained this is one of the most ignorant PIA things that Fortinet has ever done, currently 7.2 packet captures are essentially worthless IMO unless you have hours and hours to sift through convert CLI captures, etc... which is never the case. It used to be simple clean and effective actually one of favorite features and it has been turned. You would think they would be trying to make administration easier, big step backwards from previous releases.
User | Count |
---|---|
2548 | |
1354 | |
795 | |
646 | |
455 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.